Website malware removal: what a proper cleanup includes and costs
Malware removal is sold at every price from fifty to five thousand, and the cheap version is often a scan and a delete. Here is what a proper cleanup includes, step by step, how long it takes, what drives the cost, and what should come with it.
Search for malware removal and you will find every price. Some of the cheap offers are honest scans by decent people. Some are an automated tool that deletes what it recognises and calls it done. The difference shows up a month later, when the infection returns and the second cleanup costs more than a proper first one would have.
Here is what we mean by a proper cleanup, so you can compare what you are being offered.
What a proper cleanup includes
A snapshot before anything changes. Files and database. If the cleanup goes wrong you need the starting point, and if you later need to know how the attacker got in, the evidence is in that snapshot.
Finding the entry point. This is the job. Outdated software with a known hole, a compromised password, a second infected site on the same account, an old install in a subfolder. Without this, everything else is temporary. A cleanup quote that does not mention the cause is a scan, not a cleanup.
Cleaning by replacement, not by search. Core files, theme and plugins replaced with fresh copies of the same versions. Malware scanners find what they recognise; replacement removes what they do not.
The database, the config files and the scheduler. Injected script in site settings and content, changed site addresses, lines added to .htaccess and wp-config.php, scheduled tasks that reinstall the malware. These are the places scanners skip and reinfections come from.
The uploads folder and unknown files. Every PHP file where none should be. Every plugin nobody recognises.
Rotating every credential. Admin passwords, database password, secret keys, hosting login, SFTP, any API keys the site holds.
Patching and hardening. Everything updated to current. Unused plugins and themes removed. File permissions corrected. File editing disabled. A firewall in front. Two-factor login for administrators.
Getting the flags removed. If Google, the host or a blacklist flagged the site, requesting the reviews and confirming they clear.
Watching for thirty days. Daily checks for changed files, new users and new tasks. A cleanup is proven by a quiet month, not by a clean scan on the day.
A written report. What was found, where it was, how they got in, what was changed, and what you should do next. You should be able to hand it to the next person who works on the site.
How long it takes
A typical business site with one infection and a clear entry point: one to two days of work, spread over two or three calendar days because of the review waits. A site with multiple infections, an unknown entry point, or a shared account with other infected sites: a week. Multiple sites on one account: multiply accordingly, because they must all be cleaned at once.
What drives the cost
- How many sites share the account.
- Whether a clean backup exists. A restore plus patching is faster than a manual clean.
- How long the infection has been there. Older infections have more layers.
- Whether a shop or customer data is involved, which adds a breach assessment.
- Whether the site is also badly out of date, which turns the cleanup into a cleanup plus an upgrade.
What should come with it
Something that stops this happening again. A cleanup without a firewall, updates and monitoring afterwards is a cleanup with an expiry date. That is why we pair rescue work with a care plan, and why we would rather tell you that upfront than sell you the same cleanup twice.
If you want to know where you stand before talking to anyone, the scanner shows whether the site is flagged and what versions it is running. It is the first thing we look at too.
See where your own site stands.
The scanner checks the things this guide talks about, in about ten seconds, no signup.
More from the guides
Hacked WordPress: the cleanup order that holds
Most hacked sites get cleaned twice. The first time removes what you can see. Here is the full order we use so the second time is never needed: contain, find the door, clean, rotate, patch, watch.
Is my website hacked? Twelve signs, and a five-minute check
Most hacked sites look normal to their owners for weeks. The signs show up in Google, in your inbox and on other people's phones first. Here are the twelve we check, and a five-minute routine that catches most of them.
Deceptive site ahead: what it means and the fix order
Chrome is not warning about your design. Google Safe Browsing found phishing or malware on your domain. Here is what the red screen means, how to find the cause, and how to get the flag removed without it coming back.